CVE-2024-6874

Public on 2024-07-24
Modified on 2024-08-06
Description
CVE-2024-6874 is a serious security flaw in libcurl's curl_url_get() function, used for converting international domain names. When processing a name exactly 256 bytes long, it reads beyond its buffer and fails to null-terminate the string, potentially exposing or modifying stack data. This vulnerability is easy to exploit remotely without special permissions or user interaction, making it a important-severity issue with a CVSS score of 7.2. Users should apply security patches to mitigate this risk.
Severity
Important severity
Important
CVSS v3 Base Score
7.2
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 curl Not Affected
Amazon Linux 2 - Core curl Not Affected
Amazon Linux 2023 curl Not Affected
Amazon Linux 1 python-pycurl Not Affected
Amazon Linux 2 - Core python-pycurl Not Affected
Amazon Linux 2023 python-pycurl Not Affected
Amazon Linux 2 - Core python3-pycurl Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
NVD CVSSv3 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N